{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T16:34:00Z","timestamp":1778690040805,"version":"3.51.4"},"reference-count":67,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"12","license":[{"start":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T00:00:00Z","timestamp":1733011200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T00:00:00Z","timestamp":1733011200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T00:00:00Z","timestamp":1733011200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key R&amp;D Program of China","award":["2021ZD0112803"],"award-info":[{"award-number":["2021ZD0112803"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62122066"],"award-info":[{"award-number":["62122066"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U20A20182"],"award-info":[{"award-number":["U20A20182"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61872274"],"award-info":[{"award-number":["61872274"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102337"],"award-info":[{"award-number":["62102337"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key R&amp;D Program of Zhejiang","award":["2024C01164"],"award-info":[{"award-number":["2024C01164"]}]},{"name":"Key R&amp;D Program of Zhejiang","award":["2022C01018"],"award-info":[{"award-number":["2022C01018"]}]},{"DOI":"10.13039\/501100004761","name":"Natural Science Foundation of Hainan Province","doi-asserted-by":"publisher","award":["2023JJ40174"],"award-info":[{"award-number":["2023JJ40174"]}],"id":[{"id":"10.13039\/501100004761","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Young Elite Scientists Sponsorship Program","award":["2023QNRC001"],"award-info":[{"award-number":["2023QNRC001"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. on Mobile Comput."],"published-print":{"date-parts":[[2024,12]]},"DOI":"10.1109\/tmc.2024.3417930","type":"journal-article","created":{"date-parts":[[2024,6,24]],"date-time":"2024-06-24T20:13:10Z","timestamp":1719259990000},"page":"12635-12649","source":"Crossref","is-referenced-by-count":32,"title":["Does Differential Privacy Really Protect Federated Learning From Gradient Leakage Attacks?"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8771-7474","authenticated-orcid":false,"given":"Jiahui","family":"Hu","sequence":"first","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiacheng","family":"Du","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5804-3279","authenticated-orcid":false,"given":"Zhibo","family":"Wang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2763-2695","authenticated-orcid":false,"given":"Xiaoyi","family":"Pang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yajie","family":"Zhou","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6221-8142","authenticated-orcid":false,"given":"Peng","family":"Sun","sequence":"additional","affiliation":[{"name":"College of Computer Science and Electronic Engineering, Hunan University, Changsha, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1969-2591","authenticated-orcid":false,"given":"Kui","family":"Ren","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24293"},{"key":"ref3","first-page":"1","article-title":"Comprehensive privacy analysis of deep learning","volume-title":"Proc. IEEE Symp. Secur. Privacy","author":"Nasr"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref5","first-page":"2615","article-title":"Systematic evaluation of privacy risks of machine learning models","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Song"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.23919\/cje.2022.00.031"},{"key":"ref9","first-page":"14747","article-title":"Deep leakage from gradients","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhu"},{"key":"ref10","article-title":"iDLG: Improved deep leakage from gradients","author":"Zhao","year":"2020"},{"key":"ref11","first-page":"16937","article-title":"Inverting gradients-how easy is it to break privacy in federated learning?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Geiping"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref14","article-title":"Learning differentially private recurrent language models","author":"McMahan","year":"2017"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00988"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00081"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3139777"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23054"},{"key":"ref20","first-page":"267","article-title":"The secret sharer: Evaluating and testing unintended memorization in neural networks","volume-title":"Proc. USENIX Secur. Symp.","author":"Carlini"},{"key":"ref21","first-page":"1895","article-title":"Evaluating differentially private machine learning in practice","volume-title":"Proc. USENIX Secur. Symp.","author":"Jayaraman"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/tnet.2023.3317870"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00989"},{"key":"ref24","article-title":"Gradient obfuscation gives a false sense of security in federated learning","author":"Yue","year":"2022"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00978"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijmedinf.2018.01.007"},{"key":"ref27","article-title":"Understanding training-data leakage from gradients in neural networks for image classification","author":"Chen","year":"2021"},{"key":"ref28","article-title":"R-gap: Recursive gradient attack on privacy","author":"Zhu","year":"2020"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/eurosp57164.2023.00020"},{"key":"ref30","article-title":"Robbing the fed: Directly obtaining private data in federated learning with modified models","author":"Fowl","year":"2021"},{"key":"ref31","article-title":"Secure aggregation in federated learning is not private: Leaking user data at large scale through model modification","author":"Zhao","year":"2023"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"ref33","first-page":"493","article-title":"$\\lbrace${BatchCrypt $\\rbrace$}: Efficient homomorphic encryption for $\\lbrace${ Cross-Silo$\\rbrace$} federated learning","volume-title":"Proc. USENIX Annu. Tech. Conf.","author":"Zhang"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2929409"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560557"},{"key":"ref37","first-page":"5959","article-title":"Gradient disaggregation: Breaking privacy in federated learning by reconstructing the user participant matrix","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Lam"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/11787006_1"},{"key":"ref39","article-title":"Differentially private federated learning: A client level perspective","author":"Geyer","year":"2017"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP43922.2022.9747653"},{"key":"ref41","article-title":"DP-BREM: Differentially-private and Byzantine-robust federated learning with client momentum","author":"Gu","year":"2023"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59410-7_33"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3378679.3394533"},{"key":"ref44","article-title":"LDP-FL:: Practical private aggregation in federated learning with local differential privacy","author":"Sun","year":"2020"},{"key":"ref45","first-page":"2521","article-title":"Shuffled model of differential privacy in federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Girgis"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17053"},{"key":"ref47","first-page":"7232","article-title":"Evaluating gradient inversion attacks and defenses in federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Huang"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2021.3118354"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2021.3110052"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1561\/9781601988195"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref53","first-page":"13773","article-title":"Understanding gradient clipping in private SGD: A geometric perspective","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Chen"},{"key":"ref54","first-page":"17455","article-title":"Differentially private learning with adaptive clipping","volume-title":"Adv. Neural Inf. Process. Syst.","author":"Andrew","year":"2021"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref57","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2017.7966217"},{"issue":"7","key":"ref60","article-title":"Tiny imageNet visual recognition challenge","volume":"7","author":"Le","year":"2015","journal-title":"CS 231N"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"ref62","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref63","volume-title":"Digital Image Processing","author":"Castleman","year":"1996"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2022-0043"},{"key":"ref66","article-title":"Adam: A method for stochastic optimization","author":"Kingma","year":"2014"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.001.2300140"}],"container-title":["IEEE Transactions on Mobile Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/7755\/10746253\/10568968.pdf?arnumber=10568968","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,27]],"date-time":"2024-11-27T00:28:17Z","timestamp":1732667297000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10568968\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12]]},"references-count":67,"journal-issue":{"issue":"12"},"URL":"https:\/\/doi.org\/10.1109\/tmc.2024.3417930","relation":{},"ISSN":["1536-1233","1558-0660","2161-9875"],"issn-type":[{"value":"1536-1233","type":"print"},{"value":"1558-0660","type":"electronic"},{"value":"2161-9875","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12]]}}}